Posts Tagged ‘Zero-day’

Several Zero-Days on Latest WordPress CMS

WordPress CMS is now open to several vulnerabilities that allow an attacker to conduct SQL injection and run a malicious javascript on visitor’s machine over a cross site scripting bug. Actually the bug exist during the installation process so in order to take control on the remote webserver there are  condition required which an incomplete [...]

Share

Apache reverse proxy bug allows compromising internal system

Apache team is working on fixing a new vulnerability that allows an attacker from internet to have an internal access to the system. This zero day is reported by Prutha Parikh from Qualys. On a blog post published there are 2 examples on how to exploit this vulnerability with a fully patched Apache Web Server [...]

Share

Remote DoS Vulnerabilty in Apache

Apache Killer a new exploit that uses a serious Apache vulnerability discovered over 54 months ago, the bug allows hacker to conduct a denial of service attack and turn any web server down. Under certain conditions Apache internally is inefficient at handling such request which ‘explode’ into many 100′s of internal requests for large byte [...]

Share

Hackers Exploit Latest Microsoft MHTML Bug

Microsoft is investigating new public reports of vulnerability in all supported editions of Microsoft Windows. The vulnerability could allow an attacker to cause a victim to run malicious scripts when visiting various Web sites, resulting in information disclosure. This impact is similar to server-side cross-site scripting (XSS) vulnerabilities. MHTML, or Mime HTML, is a standard [...]

Share

SANS: Rising numbers of zero-day vulnerabilities

TippingPoint and Qualys two security companies have been involved in a study named “The Top Cyber Security Risks” revealed that more than half of all cyber attacks are targeting applications and websites. This report is based on information collected from March to August 2009 from customers that are using the Intrusion prevention system and network [...]

Share

Methods to Avoid Zero day attack

Updating software packages, configuring firewall properly and implementing an antivirus solution can help to guarantee good security for a home user. But when it comes for corporate information system that provides services for public network and have an outside access, security should be considered more seriously. Different vulnerabilities and interconnected system creates a new type [...]

Share

BIND 9 vulnerable to DoS

Internet Systems Consortium and US-CERT warned of a new vulnerability that concerns DNS-server code, Berkeley Internet Name Domain 9 (BIND9), this vulnerability can lead to system failure in the popular DNS BIND9. Richard Hyatt from Bluecat Networks Inc. alerted of the new zero day vulnerability and encourages all costumers to patch there servers as soon [...]

Share
Powered by WordPress | Designed by: Best SUV | Thanks to Toyota SUV, Ford SUV and Best Truck